The First Case on AI Agents: What Was Adjudicated?

marsbitPublished on 2026-06-08Last updated on 2026-06-08

Abstract

"The First 'Agent' Ruling: What Was Decided?" On April 30, the Guangzhou Internet Court issued a ruling—China's first behavior preservation order in the intelligent agent (AI agent) field. The defendant, an open-source AI agent software, was ordered to stop downloads, cease actions that bypassed a platform's technical protection measures, and delete related tutorials and data. The core issue: the software used the operating system's "accessibility service" permissions to automate user interactions within other apps without those platforms' authorization. This mirrors a recent US case where Amazon sued Perplexity for similar reasons—bypassing Amazon's API to directly scrape and interact with its pages—and won a preliminary injunction. Both rulings establish a crucial legal boundary for the AI agent era: agents cannot operate unchecked. The article argues the fundamental legal principle emerging is one of **dual authorization**. An AI agent requires both **user consent** AND **platform consent** to operate legitimately within that platform's ecosystem. Bypassing platform rules through system-level permissions, even with user permission, undermines platform responsibilities for content moderation, data security, and user privacy, creating liability issues. The piece uses the evolution of "Doubao Phone" (an AI-integrated smartphone) as a case study. Its initial, aggressive version that bypassed platform controls faced roadblocks. Its upcoming 2.0 version is reportedly pivotin...

By Wave Not Crazy

On April 30, the Guangzhou Internet Court issued a ruling.

The defendant was an open-source AI agent software. The reason for the lawsuit: It called the underlying operating system permissions without authorization, circumvented the plaintiff platform's technical management measures, and achieved automated operations.

The court ruled: Immediately stop providing downloads, immediately stop the act of circumventing technical measures, delete relevant tutorials, and delete relevant data.

This is the first behavior preservation ruling in the field of AI agents in China.

Less than two months ago, the United States District Court for the Western District of Washington was also hearing an almost identical case: Amazon sued Perplexity, alleging that the latter bypassed Amazon's API to directly operate Amazon's pages. Amazon won, and the court issued a preliminary injunction.

In two lawsuits in China and the United States, one using a behavior preservation ruling and the other a court injunction, both are setting the same "legal bottom line" for the AI agent era—AI agents cannot act recklessly.

It is said that this year AI has entered the era of agents. These two lawsuits are of significant indicative value. After digesting the news, your Bro Wave found that there is an even more thought-provoking question behind this:

Why are they the targets?

01 Two Judgments, Same Principle

If you look carefully at the complaint in Amazon's lawsuit against Perplexity, the core is just one sentence:

Perplexity bypassed our API, directly operated our pages, and undermined our technical management measures.

Translated, this means: You used our things without our permission.

There is a specific legal term for this: "circumventing technological protection measures." It is explicitly prohibited both in China's "Anti-Unfair Competition Law" and in the U.S. "Computer Fraud and Abuse Act" (CFAA).

But why Perplexity?

Because Perplexity is currently one of the most aggressive AI agent companies. Its product logic is: Users grant me authorization, and I can operate any platform on behalf of the user.

This logic sounds reasonable—the user authorized it, why should the platform interfere?

But platforms and courts see it differently.

Perplexity's official website article criticizing Amazon for being a bully

Because there is a second layer of authorization: platform authorization.

To operate Alipay, you need not only the user's consent but also Alipay's consent. To access WeChat chat records, you need not only the user's consent but also consider whether others in the group chat are aware. To operate Amazon, you need not only the user's consent but also Amazon's consent—the platform has the right to decide who can operate within its territory.

The problem with Perplexity lies in this: It only obtained the user's authorization, not the platform's.

If a small-scale AI agent company does this, the platform might not bother. But Perplexity's current daily active users have reached a level that forces Amazon to take notice.

Now look at the domestic case.

The defendant is an open-source AI agent software, with an operational logic almost identical to Perplexity's: It calls the operating system's "accessibility service" permissions to click, swipe, and input on behalf of the user.

This "accessibility service" permission was originally intended for people with disabilities, but AI agents have turned it into a tool to "bypass platform rules."

Because "accessibility service" is a permission at the operating system level, higher than permissions at the app level. Once this permission is obtained, it's like getting a "master key" that can open any house. The AI agent can then operate any app without needing separate authorization from each one.

Platforms, of course, do not welcome this "master key."

Many interpret this as commercial competition, fearing others will take their turf, but that's too simple. From a legal perspective, it's a question of whether rights and responsibilities are balanced.

Once an AI agent can bypass platform rules, all the content review, data security, and user privacy protection mechanisms that platforms have built up over the years become ineffective.

Douyin (TikTok) is not against you using external AI agents; it's against you bypassing its review mechanisms. Meituan is not against you using AI agents; it's against you bypassing its data security rules. The logic is simple: If a user's delivery address and phone number are leaked, who is responsible?

This isn't about whether you can use it; it's about who the user holds accountable if something goes wrong after using it.

02 The AI Phone Following the Trend

Speaking of this, the iterative path of a blockbuster product is worth comparing: Doubao Phone.

In 2025, Doubao Phone 1.0 chose an aggressive path: directly obtaining underlying operating system permissions from phone manufacturers to operate other apps on behalf of the user. Order takeout, hail a ride, send a WeChat message—all with one sentence.

This path soon proved infeasible. It kept running into security walls and was later forced to suspend some automated operation scenarios itself.

A product hailed as the "First Phone of the AI Era" hit a wall when facing the ecosystem.

Where did the problem lie? Again, that term: Dual Authorization.

Doubao Phone obtained user authorization but did not obtain authorization from any platforms, not even its own Douyin (TikTok). Legally, this is a "gray area"—the user did authorize it, but the platform definitely did not.

The ruling from the Guangzhou Internet Court draws a clear red line for this gray area.

Doubao Phone is also astute; it didn't confront head-on but chose a smarter path: a rapid change of course.

Recent reports indicate that Doubao Phone 2.0 will be released in the first half of the year. Unlike version 1.0, version 2.0 is negotiating authorizations one by one with ecosystem partners. It is said that agreements may have been reached with the Alibaba ecosystem, opening necessary permissions, i.e., API interface cooperation, for high-frequency scenarios like ride-hailing, food delivery, and ticket booking. This is equivalent to being compatible with Alibaba's Qianwen AI agent.

Following this win-win model, interface cooperation with WeChat, Meituan, Alipay, and JD.com is also within sight.

Looking at the judicial precedent again, you can't say Doubao Phone compromised. Rather, it demonstrates a strategic capability of recognizing the times.

The judiciary provided the answer: Bypassing platform rules won't work. So, take the proper path—negotiate one by one.

This is what a major company aiming to build a world-leading AI agent product should look like.

03 A Shared Consensus Is Forming

Looking at three things together: Amazon vs. Perplexity in the U.S., the Guangzhou Internet Court ruling, and Doubao Phone's shift from "bypassing" to "negotiating."

A global trend can be observed:

The era of unbridled growth for AI agents is over; the era of compliance competition has begun.

This shift has multi-layered impacts on the industry.

First, compliance costs are becoming the "entry fee" for AI agent companies. Before, making an AI agent only required caring about "whether it could be made." Now, they must also care about "whether it can legally operate on other platforms." This gives larger AI agent companies (those with resources to negotiate authorizations) a greater advantage. Small and medium-sized AI agent companies will either be acquired or pivot to developing "AI agents within platforms."

Second, "dual authorization" is becoming an industry standard. This actually aligns with user interests. Users aren't afraid of AI helping with operations, but they fear AI operating secretly. If every AI agent requires both "platform authorization + user authorization" to operate, users can feel more at ease.

Furthermore, open source can no longer be a reason for exemption. In the domestic case, the defendant argued, "I am open-source software, non-profit, and should not be restricted." The court did not accept this. Because open source does not equal exemption from liability. Even if you are open source, if your code is used to circumvent technical protection measures, you are responsible.

Returning to the initial question: Many are making AI agents. Why were these first penalized?

The answer is actually quite simple: It's not because they are the largest, but because they are the most aggressive and the most representative.

Perplexity is one of the most aggressive AI agent companies in the U.S. The domestic open-source software is also one of the earliest practitioners of "bypassing platform rules."

Penalizing them first isn't because they are the "worst," but because they are the "most typical."

This is a wisdom in regulation: targeting the most typical and aggressive ones makes the rest adjust on their own.

It is foreseeable that more AI agent companies will negotiate authorizations with platforms, more platforms will introduce "AI Agent Access Specifications," and fewer courts will hear similar cases.

The rules of the game for the AI agent industry have been quietly redefined.

Related Questions

QWhat are the key legal issues raised in the first domestic case involving an intelligent agent?

AThe key legal issue was that an open-source intelligent agent software allegedly bypassed the plaintiff's technical protection measures by invoking underlying OS permissions (specifically, 'accessibility services') to perform automated operations without authorization. The court ordered it to cease distribution, stop bypassing technical measures, and delete related tutorials and data, establishing that such actions violate rules against circumventing technical protection measures.

QWhy is the 'dual authorization' concept critical in regulating intelligent agents?

ADual authorization is critical because it ensures that an intelligent agent must obtain both the user's consent and the platform's authorization before operating on that platform. This prevents agents from bypassing platforms' content moderation, data security, and privacy mechanisms, which could lead to unchecked risks and unclear liability if problems arise, such as data breaches.

QHow did the Doubao Phone (Bean Bag Phone) adapt its strategy following the legal ruling?

ADoubao Phone shifted from its initial aggressive approach of using OS-level permissions to directly operate other apps without platform consent. For version 2.0, it is now negotiating API access agreements with ecosystem partners (like Alibaba) to obtain proper platform authorization, moving towards a compliant cooperation model instead of bypassing rules.

QWhat global trend does the article identify regarding the development of intelligent agents?

AThe article identifies a global trend where the era of unchecked, 'wild growth' for intelligent agents is ending, transitioning into an era of 'compliance competition.' This means legal and regulatory compliance, particularly regarding platform authorization and technical measure circumvention, is becoming a new standard and barrier to entry in the industry.

QWhat is the significance of targeting Perplexity and the open-source software in these cases according to the article?

ATargeting Perplexity and the open-source software is significant because they were among the most aggressive and representative examples of intelligent agents bypassing platform rules. By addressing these prominent cases first, regulators and courts aim to set clear legal precedents, which are expected to prompt the broader industry to self-adjust and comply, thereby efficiently shaping new rules for the entire sector.

Related Reads

Gary Yang: Agent Economy and AI Submicroeconomics

**Title:** Agent Economy and AI Sub-Microeconomics - Gary Yang **Summary:** Following the AI singularity, the pace of evolution has accelerated rapidly, creating new generational disparities in technological advancement globally. While many regions are still grappling with single-agent bottlenecks, Silicon Valley has moved ahead into the next dimension: the Agent Economy and A2A ecosystems. The article outlines six key areas of this emerging paradigm: 1. **AI Payment Competition & H2A Bottlenecks:** A fierce battle for AI Agent payment protocol standards is underway (e.g., MPP, x402). However, most current efforts remain Human-to-Agent (H2A), essentially grafting AI onto traditional human-centric commerce, which creates a non-AI-native bottleneck. The true potential lies in Agent-to-Agent (A2A) autonomous economies. 2. **Agent Economy & the Inevitable A2A Trend:** The Agent Economy is defined by autonomous AI Agents creating, exchanging, and capitalizing value as independent economic actors. The A2A ecosystem describes their interactions. This represents the next major investment frontier, akin to the early days of e-commerce or DeFi, but with faster iteration and an AI-native, efficiency-first perspective that often diverges from human needs. 3. **AI Protocol vs. Crypto Protocol:** AI Protocols are the foundational rules for Agent interaction in an open network (communication, discovery, collaboration), akin to the governance and economic laws of the AI world. Currently, they focus on communication and weak boundaries, unlike Crypto Protocols which emphasize asset rights and clear ownership. While they appear different due to political-economic factors and legacy system constraints, their eventual convergence into a unified Digital Protocol system is seen as inevitable, driven by first principles. 4. **AI Agent Sub-Microeconomics & Biological Analogy:** AI Agent economics differ fundamentally from human economics: higher frequency/lower value transactions, energy/value direct correlation, efficiency-driven (not emotional) decisions, task-oriented (not consumption-oriented) behavior, and near-zero organizational/communication costs. A powerful analogy frames the Agent economy as a biological system: the LLM is the nucleus, the Agent harness is the cytoplasm, the Agent itself is a cell, its communication protocol is the cell membrane, and external tools (Skills, Prompts) are the extracellular environment. 5. **The Inevitability of AIFi & FinChip:** AIFi (AI Finance) represents the financial system where AI-native value within the Agent economy is tokenized and exchanged. Unlike TradFi/DeFi where value resides *in* finance, in AIFi, value originates *in* AI, and finance becomes its form. This shift is enabled by Agents taking over value discovery. FinChip (Financial Chip) is introduced as a key infrastructure—a fusion of AI autonomy and crypto smart contracts—forming intelligent financial assets to power the future A2A economy. 6. **AI-Native as a Paradigm Shift:** Adopting AI is not akin to "Internet+". It requires AI-Native thinking—designing systems based on first principles, the shortest energy-value path, and maximum efficiency. This abstract, counter-intuitive logic poses a significant, ongoing challenge for all practitioners, as effective, generalized upgrade methodologies will be slow to emerge in this rapidly evolving landscape.

链捕手25m ago

Gary Yang: Agent Economy and AI Submicroeconomics

链捕手25m ago

From 'The Big Short' to San Francisco: The Revelry and Dizziness Within the AI Bubble

From "The Big Short" to San Francisco: The Frenzy and Dizziness in the AI Bubble The article captures the intense, frenetic atmosphere in San Francisco, the epicenter of the current AI boom. Drawing a parallel to the "smell of money" from *The Big Short*, the author observes a city gripped by a singular status game centered entirely on AI and technology. This manifests in a palpable, caffeine-fueled anxiety ("people are shaking"), rampant comparison using vanity metrics like funding rounds, and pervasive "Big Bubble Behavior." The piece explores the city's stark contrasts: its dystopian streets versus beautiful vistas, and the disconnect between the doomsday concerns of some AI researchers and the optimistic, growth-focused "GTM" teams. It critiques the obsession with "math genius" founders as the new ticket to outsized returns, akin to scouting sports prodigies. Referencing economic historian Carlota Perez's "frenzy phase" and Karl Polanyi's "double movement," the author frames the boom as a period where financial speculation detaches from fundamentals, with society potentially becoming subordinate to a new economic force driven by "geniuses in data centers." Ultimately, while acknowledging the unprecedented wealth creation and party-like energy, the article concludes with cautionary advice: when the music is playing, you should dance, but don't get drunk. The core reminder is to stay grounded, avoid distorted judgment, and maintain perspective amidst the euphoria.

marsbit26m ago

From 'The Big Short' to San Francisco: The Revelry and Dizziness Within the AI Bubble

marsbit26m ago

Is AI Creating a New Class of 'Information Poor'?

AI is generating a new kind of "information poverty." The core issue isn't that AI denies answers to the poor; it's that it provides abundant, cheap, and plausible-sounding answers to everyone. This availability shifts the true scarcity from obtaining answers to possessing the **judgment to evaluate them** and the access to turn them into real-world opportunities. New information poverty thus describes those who have AI tools and outputs, but lack the complementary skills, authorization, and contextual experience to critically assess and act on them. Research reveals a multi-layered divide: access to AI is stratified by income and platform design (e.g., premium vs. free, embedded tools). In workplaces, usage heavily favors higher-paid, more experienced, or formally trained employees, with AI often automating entry-level tasks that were traditional stepping stones. Crucially, the heaviest users are often mid-career professionals whose existing expertise allows them to effectively judge and leverage AI outputs, while novices risk over-relying on them without building judgment. While controlled experiments show AI can significantly boost low-skilled workers' performance, real-world adoption and benefit are constrained by unequal social and organizational structures. Historically, general-purpose technologies first reward those with existing complementary capital. AI, by affecting judgment-based work, may accelerate and deepen this initial inequality gap, even if it narrows over decades. The danger lies in the illusion of competence it creates, potentially stunting the very critical thinking needed in an era where judgment is paramount.

marsbit1h ago

Is AI Creating a New Class of 'Information Poor'?

marsbit1h ago

Jensen Huang 'Saves' South Korean Stock Market: Locks In SK Hynix Memory, Chip Shortage to Continue

On June 5th, South Korea's stock market experienced a sharp decline, with major chipmakers like Samsung and SK Hynix dropping nearly 10%. Amidst the turmoil, NVIDIA CEO Jensen Huang's visit to Seoul played a dramatic role in boosting market sentiment. Following a dinner meeting with SK Group Chairman Chey Tae-won and SK Hynix CEO Kwak Noh-Jung, Huang confirmed that NVIDIA's new Vera CPU will utilize SK Hynix DRAM. The companies announced a multi-year technical partnership to co-develop next-generation memory for NVIDIA's AI infrastructure, covering products from data centers to personal AI and robotics. This collaboration extends beyond memory supply. SK Hynix is integrating NVIDIA's AI and Omniverse platform into its own semiconductor design and manufacturing processes, including computational lithography and creating digital twins of its fabrication plants for autonomous operation. While strengthening ties with SK Hynix, NVIDIA is diversifying its supply chain for the upcoming HBM4 memory, with Samsung, SK Hynix, and Micron all certified as suppliers for its Vera Rubin platform. Despite this, Huang warned that the global chip shortage, driven by relentless demand from AI factory construction, is expected to persist for several years across the entire supply chain. His visit underscores NVIDIA's systematic effort to deepen integration with South Korea's broader tech industry.

marsbit1h ago

Jensen Huang 'Saves' South Korean Stock Market: Locks In SK Hynix Memory, Chip Shortage to Continue

marsbit1h ago

Nasdaq Plunges 4.2% in a Single Day: Does "Black Friday" Burst the U.S. Stock Market Bubble?

The Nasdaq plunged 4.18% on June 5, 2026, its worst single-day drop in over a year, as a much stronger-than-expected US jobs report triggered fears of economic overheating and delayed Federal Reserve interest rate cuts. The selloff, centered on high-valuation tech and AI stocks like Nvidia and Broadcom, spread across major indices. The article examines whether this signals a market top. The strong May non-farm payrolls data, nearly double expectations, pushed bond yields higher, directly hurting rate-sensitive tech stocks. This exposed vulnerabilities in the crowded AI trade, where valuations had soared on narratives of infinite growth, despite emerging signs of slowing order momentum and corporate AI monetization challenges. Prior to the drop, market indicators flashed warning signs: historically high valuations (e.g., Shiller CAPE ratio near 39.5), extreme bullish sentiment, and high levels of leverage. Technical charts showed key support levels being breached. Wall Street is divided on the outlook. Bears, citing risks of "stagflation" and AI bubble comparisons to the dot-com era, warn of a potential significant correction. Bulls view the drop as a healthy correction within a bull market, underpinned by a strong economy and expected corporate earnings growth of around 7% in 2026. The immediate future hinges on upcoming key events: the May CPI inflation data and the mid-June FOMC meeting. Their outcomes will critically shape market expectations for the Fed's rate path. The article concludes that conditions for a major market top are aligning, marking a fragile transition from narrative-driven gains to a phase demanding validation from macroeconomic data and corporate fundamentals. Caution is advised.

marsbit1h ago

Nasdaq Plunges 4.2% in a Single Day: Does "Black Friday" Burst the U.S. Stock Market Bubble?

marsbit1h ago

Trading

Spot
Futures

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of AI (AI) are presented below.

活动图片